In Libgcrypt 1.8.4, the C implementation of AES is vulnerable to a flush-and-reload side-channel attack because physical addresses are available to other processes. (The C implementation is used on platforms where an assembly-language implementation is unavailable.) NOTE: the vendor's position is that the issue report cannot be validated because there is no description of an attack
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libgcrypt | Nov 8, 2019 | Jun 19, 2019 |
| Huawei Euleros 2_0_sp8 | — | Upgrade libgcrypt-develUpgrade libgcrypt | Nov 19, 2019 | Jun 20, 2019 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 20, 2019 |
| Suse | — | Upgrade libgcrypt-develUpgrade libgcrypt20-hmac-32bitUpgrade libgcrypt20-hmacUpgrade libgcrypt20Upgrade libgcrypt20-32bitUpgrade libgcrypt-cavsUpgrade libgcrypt-devel-32bit | Jul 24, 2019 | Jun 20, 2019 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jun 19, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub